PublicDateAtUSN: 2015-02-08 Candidate: CVE-2014-9657 PublicDate: 2015-02-08 11:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9657 https://ubuntu.com/security/notices/USN-2510-1 Description: The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font. Ubuntu-Description: Notes: Bugs: http://savannah.nongnu.org/bugs/?43679 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777656 http://code.google.com/p/google-security-research/issues/detail?id=195 Priority: medium Discovered-by: Mateusz Jurczyk Assigned-to: mdeslaur CVSS: Patches_freetype: upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=eca0f067068020870a429fe91f6329e499390d55 upstream_freetype: released (2.5.4) lucid_freetype: released (2.3.11-1ubuntu2.8) precise_freetype: released (2.4.8-1ubuntu2.2) trusty_freetype: released (2.5.2-1ubuntu2.4) trusty/esm_freetype: released (2.5.2-1ubuntu2.4) utopic_freetype: released (2.5.2-2ubuntu1.1) devel_freetype: released (2.5.2-2ubuntu3)